JointJS is a JavaScript diagramming library primarily targeted at developers and teams building custom diagramming tools, modeling applications, or workflow editors. Implementation involves integrating the library into existing systems and tailoring its functionalities to suit user-specific use cases. The implementation timeline can vary depending on complexity and internal team capabilities.
Bullet Points:
Planning and Requirement Gathering: Understanding the scope of diagrams, models, or workflows the business wants to build; this phase includes selecting between JointJS Core and the more advanced Rappid.
Environment Setup: Setting up the development environment and dependencies such as HTML, CSS, JavaScript frameworks, and optionally Node.js or TypeScript.
Integration and Configuration: Incorporating JointJS into the frontend framework or application and configuring basic models, shapes, and interactivity.
Custom Development: Developing custom shapes, interactions, and connectors according to business-specific logic or UI/UX needs.
Testing and Iteration: Performing internal QA, validating diagram behaviors, optimizing performance, and ensuring browser/device compatibility.
Deployment: Moving the diagramming solution to production as part of the overall application or platform.
Typical Duration:
For basic integration: 1 to 2 weeks
For full customization and complex workflows: 4 to 8 weeks or more, depending on resources and goals
Customisation
JointJS offers extensive customization, particularly in its commercial extension, Rappid. It’s designed to be modular and developer-friendly, allowing full control over how diagrams look and behave.
Bullet Points:
Custom Shapes & Elements: Developers can design and implement entirely new shapes and diagram elements with unique styling and functionality.
Interactive Behaviors: Fully customizable interactions such as dragging, snapping, resizing, and connecting elements.
Custom Toolbars & UI Elements: Integration with third-party UI libraries (like React, Angular, or Vue) to create custom toolbars, side panels, or configuration menus.
Backend Integration: Capable of connecting with backend services for data persistence, validation, or real-time collaboration.
Styling & Themes: Full CSS/SVG styling control for creating branded or context-specific visuals.
Plugins & Extensions: Rappid includes plugins for export, minimap, selection tools, and more to enhance business functionality.
Additional Costs
JointJS itself is open-source, but advanced features and enterprise-grade support are part of its commercial offering, Rappid. Costs vary depending on licensing tier, support needs, and the scale of usage.
Bullet Points:
License Fee: Rappid (the commercial extension) requires a one-time or subscription-based licensing fee depending on the number of developers and use cases.
Setup Costs: While there are no mandatory setup fees, initial development and integration efforts may incur internal or third-party consultant costs.
Maintenance Costs: Ongoing internal development to maintain and update diagram functionality may add to long-term costs.
Support Charges: Paid support is available, including email support, technical consultations, and bug fixes, usually included in commercial packages or at an additional rate.
Upgrade Fees: Periodic updates and new feature releases may be tied to subscription or require additional fees if not under active support.
Training & Documentation: While documentation is comprehensive, custom training or onboarding for large teams might require external assistance at an additional cost.
Total cost of ownership depends largely on the level of customization, the number of users/developers, and support level required.
Training
JointJS, and especially its commercial extension Rappid, offers developer-focused support with strong documentation, code samples, and responsive technical assistance for paying customers. However, since it is primarily a toolkit for developers rather than end-users, the training is oriented toward implementation teams and technical staff rather than non-technical users.
Bullet Points:
Extensive Documentation: Full API reference, architecture guides, and getting-started tutorials are available for developers to learn integration and customization.
Code Examples and Demos: The official website provides a range of interactive examples and GitHub repositories to help developers understand real-world implementations.
Developer Community Access: Access to online community forums and GitHub Issues, where developers can ask questions, report bugs, and share solutions.
Commercial Support: With a Rappid license, users receive priority technical support, which may include direct communication with the development team for troubleshooting and guidance.
Email-Based Assistance: Technical inquiries are typically handled through email with response times depending on the support plan purchased.
No Formal Training Modules: There are no structured certification programs or video training series for non-developers, although some partners or third parties may offer these as services.
The learning curve is moderate to high depending on prior JavaScript and UI development experience, but strong documentation significantly reduces onboarding time for technical users.
Security Measures
As a front-end JavaScript library, JointJS does not handle data storage or transmission directly. Security responsibilities largely fall on the implementing organization, particularly in how the library is embedded and integrated with backend systems. Nevertheless, good practices and safe coding patterns are encouraged within the library’s design.
Bullet Points:
Client-Side Focus: JointJS operates entirely on the front end, meaning it doesn’t store, process, or transmit sensitive data unless developers configure it to do so.
No Built-in Data Storage: Data persistence is handled externally, allowing companies to implement secure, compliant storage on their own infrastructure.
Sanitization Capabilities: Developers are responsible for implementing input validation and sanitization to prevent injection attacks or cross-site scripting (XSS).
Secure Integration Points: When integrating with secure APIs or databases, it’s up to developers to implement HTTPS, authentication tokens, and data encryption.
Commercial Version Controls: In Rappid, additional security configurations and code auditing assistance may be available depending on the license tier.
Ultimately, the security posture depends on the implementation. JointJS provides a secure base for building upon, but enforcing robust security practices is up to the development team.
Updates
JointJS and Rappid follow a well-maintained release cycle, with regular updates introducing bug fixes, feature enhancements, and new capabilities. These are managed by the development team and communicated through official release notes and documentation.
Bullet Points:
Frequent Updates: Minor updates, bug fixes, and performance enhancements are released periodically, usually every few months.
Major Releases: Significant feature updates and architectural changes are rolled out on a less frequent basis, typically once or twice a year.
Versioning System: Updates follow semantic versioning, helping developers track compatibility and assess the impact of changes on their application.
Backward Compatibility Consideration: Updates often maintain compatibility with prior versions, but major releases may require migration efforts.
Release Notes & Migration Guides: Each update is accompanied by detailed release notes and documentation on any breaking changes or recommended practices.
Managed by Development Teams: Since it is a developer tool, update integration is handled manually by the implementing team, allowing for custom version control strategies.
Users must monitor releases and manually upgrade their local implementation, which provides flexibility but also requires developer time and testing to ensure stability.
Data Ownership and Portability
JointJS is a client-side JavaScript library, meaning it does not control, store, or manage any user or business data by default. Instead, it gives full control of data handling to the developers and organizations that implement it. This architecture inherently supports complete data ownership and portability, as all information resides on the systems of the organization using the software.
Bullet Points:
Full Data Control: Organizations retain 100% control over their data structures, diagram states, and metadata since JointJS does not store or transmit data.
No Vendor Lock-In: Because data formats and persistence mechanisms are user-defined, organizations can move, export, or migrate their data at any time without restriction.
Self-Managed Storage: All diagram data is stored wherever the organization chooses—local databases, cloud storage, or on-premise servers—offering full flexibility.
JSON-Based Models: Diagram data is often represented in standard JSON, making it easy to serialize, export, import, or convert into other formats.
Commercial License Neutrality: Rappid licensing does not alter data ownership; organizations still retain exclusive rights over all customizations and business data.
Integration Flexibility: Developers can connect JointJS to any backend system or data platform, supporting easy portability between services or vendors.
In essence, the library's structure ensures that the organization implementing JointJS remains the sole owner and controller of all data created or processed within their applications.
Scaling Up / Down
JointJS offers flexible scaling through its commercial licensing model, particularly with Rappid. While the core open-source version is freely available, scaling with enterprise-grade features, support, and performance enhancements is managed through license tiers based on usage needs, number of developers, and project scope.
Bullet Points:
License-Based Scalability: Scaling is primarily governed by the license—users can upgrade to a higher tier for more features, developer seats, or extended use cases.
Flexible Seat Licensing: Organizations can add or reduce the number of developer licenses as needed, subject to the terms of the commercial agreement.
No Usage-Based Restrictions in Core Version: The open-source version of JointJS does not impose usage limits, making it naturally scalable for non-commercial or small-scale projects.
Modular Feature Expansion: Additional capabilities like collaboration, shape libraries, export tools, and UI plugins can be added incrementally with Rappid.
Custom Enterprise Terms: Larger organizations may negotiate custom contracts that allow dynamic scaling based on project evolution or team size.
Support Tier Adjustments: As needs change, organizations can upgrade or downgrade support plans (e.g., from standard to priority support or vice versa).
Scaling JointJS is not tied to infrastructure or traffic, but rather to development and feature requirements, allowing organizations to adjust their investment proportionally to their growth or downsizing needs.
The terms & conditions for contract renewal and cancellation
JointJS, in its open-source form, is free to use under the open-source license (MPL 2.0). However, its commercial extension, Rappid, is offered under a paid licensing model. Terms for renewal and cancellation are governed by the specific licensing agreement entered into with the vendor (Client IO), which vary depending on the type of license and support package purchased.
Bullet Points:
License Duration Options: Rappid licenses may be offered as perpetual (one-time payment with optional paid updates) or subscription-based (renewable annually or monthly depending on contract).
Automatic Renewal: Subscription licenses may renew automatically unless notice is provided within the timeframe specified in the contract (typically 30 days before renewal).
Cancellation Policy: Cancellation typically requires written notice ahead of the renewal date. No refunds are generally issued for unused time in a current billing cycle unless otherwise specified.
Support Package Termination: If support is part of the contract, ending the license or downgrading may also terminate access to priority support, updates, or new releases.
Upgrade/Downgrade Flexibility: Customers can typically upgrade to a higher-tier license or support level mid-term, while downgrades may take effect only at the start of the next billing cycle.
No Data Access Restrictions on Cancellation: Since all data resides with the user organization, canceling the license does not affect access to diagrams or stored data, but feature usage may be limited post-cancellation.
Compliance
As a JavaScript-based diagramming library, JointJS does not process or store personal data itself, nor does it operate as a hosted SaaS platform. Therefore, it does not require direct compliance with standards such as GDPR, HIPAA, or SOC 2 by default. However, compliance responsibility rests with the implementing organization. The library is designed in a way that allows developers to build compliant systems around it.
Bullet Points:
Developer-Managed Compliance: Since JointJS runs client-side, organizations implementing it are responsible for ensuring compliance with relevant data privacy, security, or industry regulations.
Customizable Data Flows: Developers can integrate JointJS into systems designed for GDPR, HIPAA, or ISO 27001 compliance, depending on how data is collected, stored, and transmitted.
No Built-In Data Handling: JointJS does not have features that handle, store, or transmit personal or sensitive data—making it neutral and safe from default compliance violations.
Secure Integration Support: The library is compatible with secure development standards (like OWASP guidelines), enabling developers to enforce compliance best practices.
Enterprise Usage Readiness (via Rappid): Organizations that need compliance validation can work with the vendor (Client IO) for extended documentation or audit support under commercial contracts.
JointJS itself is a development tool that supports the creation of compliant applications, but compliance outcomes depend entirely on how the organization implements and governs its software stack.